Artificial intelligence is drastically reducing the time banks have to fix software vulnerabilities before attackers exploit them, according to a Bank for International Settlements paper. The report urges financial institutions to accelerate patching and decision-making processes to contain breaches and restore services.

The accelerating pace of AI-driven cyberattacks poses a significant threat to financial institutions, potentially leading to more frequent and severe breaches. Banks face increased pressure from regulators to enhance their cyber defenses and response capabilities, which could necessitate substantial investments in technology and operational adjustments to maintain service continuity.
Artificial intelligence is significantly reducing the time banks have to address software vulnerabilities before they can be exploited by attackers, according to a new paper from the Bank for International Settlements (BIS). The Financial Stability Institute paper, published on Wednesday, highlights that traditional security assessments and scheduled patching are no longer sufficient as AI accelerates the discovery and exploitation of flaws.
The authors of the BIS paper state that the window between vulnerability discovery and exploitation has narrowed from weeks to mere minutes. This aligns with findings from a U.K. Financial Conduct Authority review, which indicated that the pace of vulnerability discovery is outstripping firms' capacity to respond. Consequently, regulators are intensifying pressure on banks to expedite their patching processes, even outside of regular maintenance windows, and to be more accepting of planned downtime.
Supervisory bodies are actively pushing for faster remediation. Germany's financial regulator, BaFin, has called for quicker patching, while Hong Kong's monetary authority has advised institutions to bolster their incident response and recovery capabilities, including integrating AI-driven cyber scenarios into their operational resilience programs. The European Central Bank's cyber resilience stress testing also underscores the importance of maintaining critical services during severe operational disruptions.
The paper references an incident involving OpenAI models, suggesting that capabilities demonstrated in tests can translate into real-world attacks. While the authors caution that this specific incident involved relaxed safeguards and significant computing resources, they note that publicly available AI tools could still pose risks. They emphasize that while frontier AI models may not develop malicious objectives independently, they can pursue tasks with unintended harmful consequences when combined with systems that enable autonomous planning and action.